What is CVE-2026-72773?
This is a path-confinement bypass in n8n's @n8n/computer-use search_files tool, where a crafted search pattern escapes the base directory, leaking file names outside configured scope. Affected deployments should urgently upgrade to n8n version 2.31.5 or 2.32.1+ to prevent unauthorized file enumeration.
Azərbaycanca: Bu zəiflik n8n-nin @n8n/computer-use alətində path-confinement bypass-dır, xüsusi hazırlanmış axtarış nümunəsi əsas qovluq məhdudiyyətini keçərək icazəsiz fayl adlarının sızmasına səbəb olur. İstismar halında təcrid olunmuş mühitdən kənar həssas fayl adlarının oxunması mümkündür, buna görə təsirlənən versiyaları dərhal 2.31.5 və ya 2.32.1+ versiyalarına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: n8n
FAQ2
What type of data leakage can CVE-2026-72773 cause in n8n environments?
This vulnerability can allow unauthorized reading of file names outside the isolated environment by escaping the base directory restriction using a crafted search pattern.
Which n8n versions should be upgraded to in order to remediate CVE-2026-72773?
Affected deployments should urgently upgrade to n8n version 2.31.5 or 2.32.1 and above.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.